Websocket Vulnerability in GeoWebPlayer by GeoVision
CVE-2026-13125
8.8HIGH
What is CVE-2026-13125?
GeoWebPlayer, an addon for GeoVision's software suite, has a vulnerability that allows unauthorized access to its websocket server. This lack of authentication could enable attackers to interact with sensitive API endpoints. Specifically, an attacker could exploit this vulnerability to invoke methods such as create and getScreenCapture, potentially leading to unauthorized access to a user's screen content.
Affected Version(s)
GeoWebPlayer Windows V1.1.1.0
GeoWebPlayer Windows V1.1.3.0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Philippe Laulheret of Cisco Talos
Kelly Patterson of Cisco Talos
Robert Sherwin of Cisco Talos
